GadgetBond

  • Latest
  • How-to
  • Tech
    • AI
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Add GadgetBond as a preferred source to see more of our stories on Google.
Font ResizerAa
GadgetBondGadgetBond
  • Latest
  • Tech
  • AI
  • Deals
  • How-to
  • Apps
  • Mobile
  • Gaming
  • Streaming
  • Transportation
Search
  • Latest
  • Deals
  • How-to
  • Tech
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • AI
    • Anthropic
    • ChatGPT
    • ChatGPT Atlas
    • Gemini AI (formerly Bard)
    • Google DeepMind
    • Grok AI
    • Meta AI
    • Microsoft Copilot
    • OpenAI
    • Perplexity
    • xAI
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Follow US
EntertainmentSecurityStreamingTech

Plex confirms new security breach and urges all users to reset passwords

Plex is warning customers of an unauthorized database access that revealed limited account information and is advising immediate password resets with two-factor authentication enabled.

By
Shubham Sawarkar
Shubham Sawarkar's avatar
ByShubham Sawarkar
Editor-in-Chief
I’m a tech enthusiast who loves exploring gadgets, trends, and innovations. With certifications in CISCO Routing & Switching and Windows Server Administration, I bring a sharp...
Follow:
- Editor-in-Chief
Sep 9, 2025, 12:31 PM EDT
Share
A flat-screen display showing the Plex logo against a gradient background that transitions from pink to purple. The Plex logo features white lowercase letters "plex" with a distinctive yellow "x" that resembles a forward arrow. The screen has a thin black bezel and is positioned at an angle against a deep purple background, creating a modern, sleek appearance.
Image: Plex
SHARE

If you use Plex — the slick little app that turns a dusty hard drive into a streaming service for your living room — you probably woke up today to an email asking you to do the thing every tech company asks when something goes wrong: change your password. This isn’t a routine nudge. Plex says an “unauthorized third party” accessed one of its databases and read a limited set of account details, including email addresses, usernames and securely hashed passwords. The company is asking affected users to reset passwords, sign out connected devices, and turn on two-factor authentication (2FA).

Déjà vu for Plex users

For anyone who remembers the 2022 incident (and the forum breaches before that), this will feel uncomfortably familiar. Plex has had to tell users to reset passwords before — and that history makes today’s notice sting a bit more. That earlier episode saw similar account details exposed and left a lot of folks asking whether anything meaningful had changed on Plex’s security front since then.

What Plex says (and what that actually means)

Plex’s notice, posted on its forum and sent by email, says an “unauthorized third party” got into a database and that the data included emails, usernames and securely hashed passwords. Plex also stresses it doesn’t store customers’ credit card data on its servers, so payment details weren’t part of the leak. The company says it contained the incident and fixed the access vector, and it’s conducting additional security reviews.

“Securely hashed” is not the same as “stolen in plaintext.” Hashing is a one-way transform that makes raw passwords unreadable, and good hashing practices include salts and slow algorithms that make cracking expensive. That’s why Plex is not saying the attacker grabbed plain passwords. But hashed passwords still have value to attackers — if a password is weak, or if a user reused the same password across sites, a determined attacker can crack hashes offline or try those credentials on other services. In short, hashed is better than plaintext, but it is not a free pass to ignore the warning.

Exactly what you should do (right now)

Plex’s ask is straightforward. Do these three things immediately:

  1. Reset your Plex password at https://plex.tv/reset. When you do, check the box that signs out connected devices — that will force any already-logged sessions (including your Plex Media Server instances you run at home) to require the new password. Yes, it’ll be mildly annoying — but that’s the point.
  2. Enable two-factor authentication on your Plex account. Plex documents how to enable 2FA on your account page; once enabled, logins will require a short time-based code in addition to your password. This blocks a lot of common account takeover attempts.
  3. If you reuse passwords anywhere, change them there, too. Attackers often test breached credentials on other services. Adopt unique, strong passwords and use a password manager if you don’t already. For an extra check, you can paste your email into services like Have I Been Pwned to see whether it has appeared in prior breaches.

A few practical notes for Plex server owners

If you run a Plex Media Server at home, the “sign out connected devices” option will sign out whatever devices are currently authenticated — that includes clients and server sessions. Expect to re-authenticate apps and possibly re-enter tokens for companion apps or integrations that don’t support 2FA. If you manage shared libraries for friends and family, give them a heads-up: they’ll need to sign back in after you reset your account. Plex’s support pages and forum thread for this notice are where the company’s official instructions live.

Don’t fall for the follow-on scams

Breaches are also magnets for phishing. Plex explicitly reminded customers that they will never ask for your password or credit card over email, and attackers will try to imitate urgent notices to trick people into handing over credentials. If you get an email telling you to click a strange link or call a number, don’t. Go straight to plex.tv (type it into your browser) or the official support site; don’t follow links in unsolicited messages.

Why incidents like this keep happening

There’s no single, simple answer, but a few patterns repeat across breaches: legacy systems and forgotten access paths, credential stuffing (reused passwords), stolen third-party credentials, and vulnerabilities in tooling that companies rely on. Plex says it “addressed the method” the attacker used and is hardening systems — but for users, the best defence is good credential hygiene (unique passwords + 2FA) and a little skepticism about urgent messages. Security teams can and should keep patching and auditing, but the last line of defence is often the account holder.

If you want to be cautious (extra steps)

  • Use a password manager to generate and store unique passwords.
  • Turn on 2FA everywhere it’s available, not just Plex.
  • Check your email with a breach-watcher such as Have I Been Pwned and sign up for alerts.

Plex’s message is short and sensible: some account data was exposed; passwords were hashed; reset yours; enable 2FA; sign out connected devices. If you think about the risk realistically, the main danger isn’t that Plex stores your credit card number or private messages — the danger is password reuse. If you use the same password on other sites (banking, email, shopping), start changing them now. The fix is boring, but effective: new passwords, unique passwords, and two-factor authentication.


Discover more from GadgetBond

Subscribe to get the latest posts sent to your email.

Most Popular

Anthropic launches full Claude Platform on AWS with native integration

Quick Share’s AirDrop support is coming to more Android brands

Anthropic rolls out fast mode for Claude Opus 4.7 on API and Claude Code

Anthropic ships agent view to tame your Claude Code chaos

Google adds Gemini AI and auto browse to Chrome on Android

Also Read
Anthropic logo displayed as bold black uppercase text on a light beige background.

Anthropic and Gates Foundation seal $200 million AI deal for global good

Illustration showing an AI-assisted financial workflow interface connected to business apps and spreadsheets. On the left, a dark panel contains a prompt requesting payroll cash position analysis using QuickBooks and PayPal data, along with reminders for overdue invoices. Below the prompt are connector buttons for Intuit QuickBooks and PayPal. On the right, a Microsoft Excel spreadsheet titled “April-Payroll-Reconciliation.xlsx” displays account balances, payroll obligations, reserve targets, projected cash flow, and highlighted financial gaps using color-coded cells. The background features a soft green abstract pattern.

Anthropic launches Claude for Small Business with deep app integrations

Close-up top view of two Nothing Ear (open) Blue earbuds on a light gray background. The earbuds feature curved open-ear hooks in pastel blue, metallic silver stems, and transparent housings that reveal internal components with distinctive red and white circular accents.

Nothing Ear (open) now comes in a soft blue for $99

Minimalist Android logo on a light gray background. The image features the word “Android” in black text alongside the green Android robot head mascot with antennae and black eyes.

Android 17 brings big upgrades for creators

Wide in-car infotainment display showing the Android Auto interface with navigation, messaging, and music controls. The main screen features a 3D-style map with driving directions to Seneca Street, route guidance, and estimated travel time. A sidebar on the left provides quick access to apps such as Google Maps, Spotify, phone controls, and system settings. On the right, a notification panel shows a new message from “Jennifer Travis,” while a Spotify music widget displays the song “You Got to Listen” by Michael Evans with playback controls. The interface is designed for multitasking while driving.

Android Auto’s big upgrade brings 3D Maps, video and Gemini to your car

Three smartphone screens demonstrating data transfer from an iPhone to an Android device. The left screen shows an iPhone “Apps and Data” page where users can select items to transfer, including apps, app data, passwords, accessibility settings, and accounts. The center Android screen displays a progress interface with the message “Copying your data...” and animated graphics while the transfer is in progress. The right Android screen confirms the transfer is complete, listing successfully copied items such as apps, calendars, contacts, files, and home screen layout, with checkmarks beside each category.

Google and Apple just made switching from iPhone to Android feel painless

Illustration showing three Android smartphone screens demonstrating a digital wellbeing or focus feature called “Pause Point.” The left screen displays a calming breathing exercise with the text “Breathe in” inside a large rounded shape. The center screen asks users to set a timer for an app called “Tiny Knight,” offering options for 5, 15, or 30 minutes. The right screen suggests alternative activities with the message “Why not focus elsewhere?” and lists apps like Fitbit, Play Books, and Mellow Mindspace. Each screen includes a blue action button such as “Don’t open” or “Close app,” emphasizing mindful app usage and screen time management.

Pause Point for Android adds a 10-second speed bump to distracting apps

Colorful collage of assorted emoji icons arranged in a grid on a light gray background. The image includes a wide variety of emojis such as food items, animals, weather symbols, objects, nature elements, facial expressions, and activities. Visible emojis include pizza, tiger face, fireworks, bacon, cat face, rainbow, sloth, pumpkin, books, diamond, fire, money bag, UFO, guitar, gift box, violin, and many others, creating a playful and vibrant emoji-themed pattern.

Android is getting a full 3D emoji makeover with Google’s Noto 3D

Company Info
  • Homepage
  • Support my work
  • Latest stories
  • Company updates
  • GDB Recommends
  • Daily newsletters
  • About us
  • Contact us
  • Write for us
  • Editorial guidelines
Legal
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • DMCA
  • Disclaimer
  • Accessibility Policy
  • Security Policy
  • Do Not Sell or Share My Personal Information
Socials
Follow US

Disclosure: We love the products we feature and hope you’ll love them too. If you purchase through a link on our site, we may receive compensation at no additional cost to you. Read our ethics statement. Please note that pricing and availability are subject to change.

Copyright © 2026 GadgetBond. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | Do Not Sell/Share My Personal Information.